Loading HuntDB...

GHSA-q9r8-89xr-4xv4

GitHub Security Advisory

MindsDB Deserialization of Untrusted Data vulnerability

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when used for a prediction.

Affected Packages

PyPI mindsdb
Affected versions: 23.10.2.0 (last affected: 24.9.2.1)

Related CVEs

Key Information

GHSA ID
GHSA-q9r8-89xr-4xv4
Published
September 12, 2024 3:33 PM
Last Modified
September 16, 2024 10:34 PM
CVSS Score
7.5 /10
Primary Ecosystem
PyPI
Primary Package
mindsdb
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 9, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.